On Tracking Ransomware on the File System

1Citations
Citations of this article
10Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Ransomware detection is gaining growing importance in the scientific literature because of widespread andeconomic impact of this type of malware. A successful ransomware detection system must identify a malicious behaviour as soon as possible while reducing false positive detection. To this end, different strategies have been explored. Recently, a promising approach has risen. It consists in looking for possible running ransomware by measuring the different activities every process does on the filesystem. Such measurements are represented with quantitative “indicators”. Indicators selection and their interpretation, is a critical and challenging task. In this paper we survey some of most representative file-system centered ransomware detectors and describe their chosen behavioural indicators and strategies used to measure them. Then we compare the different solutions and discuss pros, cons and open issues of every approach.

Cite

CITATION STYLE

APA

Catuogno, L., & Galdi, C. (2022). On Tracking Ransomware on the File System. In International Conference on Information Systems Security and Privacy (pp. 210–219). Science and Technology Publications, Lda. https://doi.org/10.5220/0010985000003120

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free